SushiSwap denies reports of billion dollar bug

SushiSwap denies reports of billion dollar bug

The developer behind popular decentralized exchange SushiSwap has rejected a purported vulnerability reported by a white-hat hacker snooping through their smart contracts.

According to media reports, the hacker claimed to have identified a vulnerability that could place more than $1 billion worth of user funds under threats, stating they went public with the information after attempts to reach out to SushiSwap’s developers resulted in inaction.

Our top trading bots

The hacker claims to have identified a “vulnerability within the emergencyWithdraw function in two of SushiSwap’s contracts, MasterChefV2 and MiniChefV2” — contracts that govern the exchange’s 2x reward farms and the pools on SushiSwap’s non-Ethereum deployments such as Polygon, Binance Smart Chain and Avalanche.

While the emergencyWithdraw function allows liquidity providers to immediately claim their LP tokens while forfeiting rewards in the event of an emergency, the hacker claims the feature will fail if no rewards are held within the SushiSwap pool — forcing liquidity providers to wait for the pool to be manually refilled over a roughly 10-hour process before they can withdraw their tokens.

“It can take approximately 10 hours for all signature holders to consent to refilling the rewards account, and some reward pools are empty multiple times a month,” the hacker claimed, adding:

“SushiSwap’s non-Ethereum deployments and 2x rewards (all using the vulnerable MiniChefV2 and MasterChefV2 contracts) hold over $1 billion in total value. This means that this value is essentially untouchable for 10-hours several times a month.” 

However, SushiSwap’s pseudonymous developer has taken to Twitter to reject the claims, with the platform's "Shadowy Super Coder Mudit Gupta stressing that the threat described “is not a vulnerability” and that “no funds are at risk.”

Gupta clarified that “anyone” can top up the pool’s rewarder in the event of an emergency, bypassing much of the 10-hour multi-sig process the hacker claimed is needed to replenish the rewards pool. They added:

“The hacker's claim that someone can put in a lot of lp to drain the rewarder faster is incorrect. Reward per LP goes down if you add more LP.”

Related: SushiSwap’s token launchpad, MISO, hacked for $3M

The hacker said they had bee instructed to report the vulnerability on bug bounty platform Immunefi — where SushiSwap is offering to pay rewards of up to $40,000 to users that report risky vulnerabilities in their code — after they first reached out to the exchange.

They noted that the issue was closed on Immunefi without compensation, with SushiSwap stating they were aware of the matter described.

Continue reading at Cointelegraph
1inch Network adds a P2P feature to facilitate secure crypto swaps
The decentralized exchange aggregator 1inch Network introduced peer-to-peer, or P2P, order functionality within the 1inch decentralized application, or...
Analysts say Bitcoin 'bottom is in’ as BTC bounces back to $38,000
The ongoing tensions between Russia and Ukraine continue to be the dominant news story on Feb. 22 as Bitcoin (BTC) and the wider global financial tremble...
Buzzfeed’s Bored Ape NFT dox: Danger to crypto or journalistic integrity?
From the very beginning, individuals making use of pseudonymous identities to protect their privacy has been an integral part of the crypto sector, however,...
NFL to offer virtual NFT tickets at Super Bowl in Los Angeles
The NFL announced officially on Wednesday that each fan who attends Super Bowl LVI in Los Angeles on Feb. 13 will receive a unique customized nonfungible...
Portal partners with Polygon to advance DeFi on Bitcoin
Decentralized exchange, or DEX, and self-custody wallet platform Portal has announced a strategic partnership agreement with layer-two blockchain network...
Price analysis 8/9: BTC, ETH, BNB, ADA, XRP, DOGE, DOT, UNI, BCH, LINK
Bitcoin’s (BTC) recovery from $29,482.61 on July 21 has continued to surpass one resistance after another. Today, Bitcoin has risen above the 200-day simple...
Bitcoin rally puts $40,000 in view as Amazon steps up crypto push
By Samuel IndykInvesting.com – The price of Bitcoin was approaching $40,000 early on Monday morning after a weekend rally saw the world’s largest cryptocurrency...
Barclays tells cardholders it's stopping payments to Binance
Customers have been reporting that Barclays, a British multinational universal bank, has been blocking payments to Binance cryptocurrency exchange over...
Colombian capital supports blockchain and emerging tech with $2.3M fund
Colombia’s capital of Bogotá is funding blockchain development as part of the city’s broader investment in innovative technologies.According to a Monday...
Understanding the systemic shift from digitization to tokenization of financial services
The financial industry has seen a rise in demand for exposure to digital — and crypto — assets in all asset classes. This has led to interest, demand and...
Top 5 cryptocurrencies to watch this week: BTC, XRP, DOT, XLM, SOL
Bitcoin (BTC) has been struggling to rise above the $50,000 mark, which could have resulted in traders dumping their Bitcoin positions to invest in altcoins....
Bitcoin whale MicroStrategy buys additional 271 BTC
MicroStrategy, a Virginia-based business intelligence firm, has added another 271 Bitcoin (BTC) to its strategic reserves, underscoring CEO Michael Saylor’s...
100,000 investors deluge Casper Labs’ token sale, with most expected to miss out
That’s about 10X more hopefuls than are likely to secure tokens in the sale.It’s the first of three phases to Casper’s token sale and commenced on March...
South Korea Assures No Ban For Cryptos As $600 mln Unlawful Trades Revealed
On Wednesday, January 31, cryptocurrency market keeps sinking in red even though the finance minister of South Korea reassured the authorities do not have...
Tom Lee Says BTC Will Outperform After Wreck, Crypto Market Goes Down Again
It seems that everybody will remember 2018 first market crash in mid-January when bitcoin’s price dropped to $9,402 per unit from relatively stable $14,000...